skill-harmonization
Warn
Audited by Socket on Aug 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS due to install/execution trust rather than overt malicious logic. The skill’s stated purpose matches its repository and skill-inventory behavior, and it does not ask for credentials or explicit network exfiltration, but it depends on an unverifiable external CLI (`ai-skillet`) that receives repository and user-skill metadata, so the trust boundary is too broad to rate benign.
Confidence: 84%Severity: 78%
Audit Metadata